09-05-2012 07:40 PM
I just found this article about Upek Protector suite being vulnerable to hacking of the registry stored password. My W520 comes with an AuthenTec (who bought UPEK) TouchChip Fingerprint Coprocessor.
http://arstechnica.com/security/2012/09/windows-pa
The Lenovo Fingerprint Software looks like a rebranded version of Upek Protector Suite. Is this true?
Solved! Go to Solution.
09-05-2012 10:26 PM
Any and every kind of password utility can be and is hackable.
09-05-2012 11:53 PM
Eclipsed830 wrote:Any and every kind of password utility can be and is hackable.
True but this is an egregious fault that Lenovo needs to take very seriously.
09-06-2012 01:33 PM
All,
We are aware of the article and are investigating the report.
Thanks
Mark
09-21-2012 01:34 AM
09-21-2012 11:00 AM - edited 10-01-2012 07:06 AM
tgrmas,
Thanks for the prompt - I had been meaning to get back to this topic...
Our engineering team responsible for the fingerprint scanner worked with AuthenTec (who purchased Upek) and shared the following summary based on AuthenTec and our own analysis...
"We agree with AuthenTec's position that the attack on users' Windows passwords is not as trivial as the article claims. Any tool that would execute the attack would need to be run with Administrator privileges -- an access level that would let any number of security hacks, such as keyloggers, to be run. AuthenTec will provide a software patch that will protect against attacks to their encryption algorithm, and will resolve the reported issue. We are working with AuthenTec to port this patch to our ThinkVantage Fingerprint Software (TFS). This patch which will be backward compatible with existing versions of TFS, and will soon be made available for our customers on the Lenovo website and as a critical update on ThinkVantage System Update."
I'll update here with links once the patch is available for download (or through TVSU).
EDIT 10/1/12 Patch now available for download here.
Thanks,
Mark
09-22-2012 02:26 PM
I found this on the Lenovo site dated (18 Sep 2012): Thinkvantage Update suggests it as an optional install. (No previous version installed) What is it for? Would I need it if I use a non-Lenovo password manager (LastPass for example). --------------------------------------------------
ThinkVantage Fingerprint Software enables:
Version 5.9.7.7226
System requirements
ThinkVantage Fingerprint Software can be installed on any computer with the following requirements:
Administrator rights are required to install or uninstall ThinkVantage Fingerprint Software.
Note: If using SafeGuard Enterprise (SGN) 5.5 and Windows 7 you should use UPEK FPR SW 5.8.6.6874 instead of 5.9.7.
09-26-2012 06:20 PM - edited 09-26-2012 06:41 PM
Patch is now available on TVSU as of 9/26/12 (5.9.7.7261)
09-27-2012 08:41 AM
harrisb wrote:Patch is now available on TVSU as of 9/26/12 (5.9.7.7261)
My TVSU (ThinkVantage System Update) offers me Version 5.9.7.7226.
ThinkVantage System Update also says "no previous version installed"
But my fingerprint reader works OK for logon and with LastPass.
What does Lenovo Fingerprint Softwar software do?
Do I even need it if I have LastPass?
I am confused ...
09-27-2012 08:45 AM
That's because you need the latest base code upon which to install the patch. The Lenovo Fingerprint software works with the Password Manager and BIOS system login. Other Windows applications can enable the biometric devices on the system, but they will not interface with the BIOS on the W520.